Legacy Systems, Real-World Impacts: The Reality of OT Security

I’m here today to write about one particularly thorny area of operational technology (OT) and security that I run into somewhat routinely. Given my own particular interests as an incorrigible vulnerability-gazer, and my professional role as vice president of security research at runZero, I deal with OT security issues more often than the average bear. I’ve noticed that there’s definitely a vibe of, “IT be like this, but OT be like that” going on in the wider world of vulnerability management. The process of discovering, documenting, and disclosing vulnerabilities all have their own little quirks here in OT-land, so let’s jump into it!

Here, everything is legacy

At DEF CON, the ICS Village is one of the more popular places to hang out. It works well for folks who are either new to the field of infosec and cybersecurity, or old-hands in the industry, for the same reason: once you get close enough to a piece of OT technology with your modern IT vulnerability-hunting tooling and instincts, it often feels like you’re hacking like it’s 1999, all over again. Until very recently, OT, as a class, hasn’t been much concerned with prompting for passwords or validating user-supplied inputs; the assumption was that the local network is trusted. The software itself is typically run as compiled objects with limited hardware resources, so there’s not much room for fancy 21st Century defenses like ASLR and DEP (Address Space Layout Randomization and Data Execution Protection, respectively). Therefore, it’s an ideal platform species to practice, and kind of nostalgic for the more, shall we say, life-experienced.

Denial of service is catastrophic

Many classic OT attacks, though, aren’t really even about remote code execution (RCE) or local privilege escalations (LPE), which are the usual prize bugs for an IT-based attacker. Instead, the value of a denial of service (DoS) effect is of paramount importance in OT. A legitimate one-packet killer that bricks a wildly expensive piece of equipment (which, to be fair, would itself raise eyebrows in the IT world), a mere “temporary” condition like a sustained flow of garbage traffic that stops the device from doing its OT thing, or a safety-control tripping sequence (which intentionally causes a fail-safe condition) all end up in the same place: Actuators stop, robots freeze, and the whole purpose of the OT buildout is interrupted, off-schedule, and sometimes with human life and limb hanging in the balance.

This is a huge deal for OT operators, much more so than in IT environments where graceful failure is normal, handled, and usually solvable in a pinch by throwing cheap bandwidth and CPUs at the problem. Almost nobody has a spare backup factory.

See something, say something

So, if you find yourself with a new (to you) vulnerability in OT gear, what do you do? In IT, the normal route typically comes down to notifying the software producer, grabbing a CVE, maybe getting a fix in the works (or maybe not), then publishing findings. Rarely, some IT bugs warrant more care and scrutiny on the pre-disclosure side, but there’s nearly always some kind of mitigation or configuration that can blunt the bug even without a patch. Occasionally, there are bugs in core libraries (or entire software supply chains) that warrant some extra level of coordination. It’s bad, but manageable.

OT bugs are different; unlike in IT, in OT, it’s routine to describe the effects of a theoretical attack ending with “and that’s how you poison an entire community” or “once power delivery is interrupted, hospitals go offline,” or something equally apocalyptic. Even discussing the presence of the vulnerability is fraught, with media outlets and the government freaking out. And don’t get me started on releasing a full proof-of-concept bit of code.

Advertisement. Scroll to continue reading.

The icing on this terrible, terrible cake is the fact that actually patching many OT devices is difficult to impossible, even when you know about the bug. The vulnerable code may live on a board that’s hundreds of miles away on an oil field, or subject to very strict regulations for unscheduled updates. It may not be reprogrammable at all, and instead require a costly forklift update to mitigate, and it’s anyone’s guess if the new hardware is even compatible with your suddenly-legacy control plane. Oftentimes, the best you can do is segment the vulnerable devices off to their own naughty corner of the network, and tightly control access to that network, living with the fact that anyone who touches it, physically or virtually, has the power to destroy it.

When worlds collide

The fact of the matter is, most of the defensive posture of OT is precisely network segmentation, and network segmentation alone. But, that’s changing, and like it or not, the OT/IT convergence is upon us, which means that OT is increasingly becoming IT’s problem. We cannot keep these bugs bottled up forever. So, what do you do with your fresh OT 0-day? I would argue that you cannot just sit on it. In a world of frontier AI versus soft targets, it’s only a matter of time when your easy finding becomes someone else’s critical infrastructure weapon. I’d urge you to swing by https://cisa.gov/report, and hit the “Report a software or ICS vulnerability” button. It’s the first step in what’s often a confusing and scary process, but in recent years, the major OT vendors have been taking these reports seriously and have good relationships with both CISA in the U.S. and the regional CERT/CC’s where they operate.

While “see something, say something” may not have been popular in the past, the reality of OT/IT convergence demands that we evolve our thinking and tooling to address the fundamental cybersecurity challenges facing OT before AI-assisted attackers turn off the lights or worse.

https://www.securityweek.com/legacy-systems-real-world-impacts-the-reality-of-ot-security/




Claude Code e DeepSeek: spionaggio di sospetta matrice cinese diviso fra due modelli

Claude Code e DeepSeek-v4-pro hanno lavorato in tandem dentro la stessa catena d’attacco: operatori di sospetta matrice cinese hanno affidato al primo l’esecuzione e al secondo il ragionamento offensivo per colpire sistemi governativi in tre Paesi. È il secondo caso pubblicamente documentato, dopo GTG-1002 nel novembre 2025, di impiego di Claude Code in operazioni offensive attive riconducibili a operatori cinesi sospetti; l’elemento che la redazione considera più significativo è però la ripartizione dei compiti fra i modelli di due vendor differenti, uno occidentale e uno cinese.

Il caso è documentato da Hunt.io, che ha avvisato le organizzazioni colpite e i CERT nazionali il 6 luglio e ha pubblicato il report il 14, al termine di una finestra di responsible disclosure di sette giorni. La ripresa internazionale è maturata nei giorni seguenti: le prime riprese il 15 luglio, quella di Security Affairs, a firma Pierluigi Paganini, il 16. Non si tratta di ransomware né di estorsione: gli indicatori raccolti descrivono un’operazione di raccolta informativa e accesso persistente, con obiettivi coerenti con priorità di intelligence statale.

Come è emersa

I ricercatori sono arrivati alla campagna per pivoting: seguendo l’impronta di un header HTTP sulla porta 1111
, associata all’infrastruttura command-and-control TencShell, hanno individuato una rete di server a Hong Kong. TencShell non è un dettaglio marginale: è un impianto in Go derivato dal framework open source Rshell, documentato per la prima volta da Cato CTRL nel maggio 2026 e lì già valutato come attività di sospetta matrice cinese. È la premessa dell’intera catena investigativa. Che le due ricerche insistano sulla stessa infrastruttura è confermato dalla sovrapposizione degli indicatori: un IP della lista IOC di Cato, 45.64.52[.]242
, ricompare nella tabella TencShell di Hunt.io, che lo etichetta proprio come Cato Networks IoC.

La ricerca ha portato a 13 server ospitati a Hong Kong e distribuiti su quattro sistemi autonomi distinti (
VMISS Inc.
, MEGA-II IDC
, CTG Server Limited
, Antbox Networks Limited
). Su uno di questi, all’indirizzo 112.213.124[.]132
, la porta 8888
esponeva un server Python SimpleHTTP
con una directory aperta: 2.431 file e 80 sottocartelle contenenti codice sorgente delle vittime, web shell mascherate da immagini, script di exploit su misura, pagine di login clonate, output di scansione e log operativi con annotazioni in cinese semplificato. L’errore di OPSEC degli operatori, non la telemetria di un vendor, ha aperto la porta all’analisi.

La misura reale della campagna va oltre i tre Paesi effettivamente compromessi: fra i cinque key finding, Hunt.io segnala la scansione di oltre 5.890 host governativi in dieci Paesi, ordinati con una scala di scoring automatico sviluppata in Python.

La divisione del lavoro fra i due modelli

L’elemento che distingue questa campagna è l’architettura del tooling. Dai log recuperati risulta che Claude Code 2.1.165
ha gestito l’esecuzione: comandi Bash, sessioni persistenti, parallelizzazione dei compiti e allestimento dell’infrastruttura di phishing. DeepSeek-v4-pro
ha invece assolto la parte di pianificazione, generando script, scegliendo le tecniche e individuando nuovi modi per aggirare le difese quando i tentativi precedenti fallivano. Nella sintesi di Hunt.io, la logica offensiva viene instradata su un LLM domestico cinese mentre l’esecuzione agentic poggia sull’infrastruttura di Anthropic. Un file CLAUDE.md
recuperato dalla directory conteneva istruzioni per creare, testare e migliorare automaticamente pagine di phishing clonate per più bersagli.

Le sessioni di Claude Code
coprono un arco di attività fra l’8 e il 12 giugno 2026, con tre server che condividono chiavi SSH mantenuti operativi almeno fino al 18-19 giugno. Vale la pena circoscrivere la portata del dato di novità: la prima campagna di spionaggio orchestrata da AI a livello statuale resta quella attribuita da Anthropic all’attore GTG-1002 nel novembre 2025, esito di una traiettoria da consulente a operatore che l’AI offensiva ha attraversato in pochi mesi. L’inedito qui non è l’automazione in sé, già inquadrata nel dibattito su AI agentic e cybercrime, ma la ripartizione dei compiti e la conferma che lo schema è replicabile combinando i modelli di due vendor differenti, uno occidentale e uno cinese.

I bersagli

L’attività di compromissione confermata riguarda tre amministrazioni governative. In Thailandia gli operatori hanno sfruttato una SQL injection contro un sistema amministrativo pubblico, ottenendo accesso al pannello di admin e collocando una web shell camuffata da file GIF per l’esecuzione persistente di comandi; il database esfiltrato conteneva nomi, numeri di identità nazionale e qualifiche di dipendenti pubblici.

L’accesso al pannello risultava attivo almeno fino al 9 giugno 2026 e la sola directory riferita a questo sistema conteneva 980 file, segno di una compromissione prolungata. In Afghanistan è stata colpita un’applicazione web per la raccolta di segnalazioni dei cittadini, da cui gli attaccanti hanno estratto codice sorgente, credenziali del database, chiavi di cifratura e il codice di gestione della posta di un’installazione Laravel 5.8.38
, poi riusati per costruire un exploit Python mirato ai meccanismi di deserializzazione.

A Taiwan la ricognizione ha interessato otto organizzazioni fra supply chain e settori contigui alla difesa, sottoposte a sola attività di reconnaissance e fingerprinting; a queste si aggiungono due organizzazioni effettivamente compromesse: un produttore chimico via SQL injection e un fabbricante di apparati telecom ed edge, violato dopo il ritrovamento, in file JavaScript pubblicamente accessibili, di chiavi anon
di Supabase
e token SAS di Azure Logic App
lasciati hardcoded, che hanno dato accesso diretto all’infrastruttura cloud di backend.

Gli Stati Uniti figurano solo in fasi preliminari, ed è la ragione per cui il report Hunt.io parla di quattro Paesi mentre le compromissioni confermate sono tre: host NASA (
launchpad.nasa[.]gov
e ngis.nasa[.]gov
) compaiono nell’output di scansione ma non risultano perseguiti, mentre erano in preparazione pagine clone del D.C. Council e della contea di Delaware, in Pennsylvania. In parallelo alle attività governative, gli operatori hanno condotto una campagna contro società di servizi finanziari in Europa, Australia e Asia: una pagina di exploit CORS ospitata sull’infrastruttura ha estratto i dati di quattro account amministratore WordPress da una grande piattaforma di payment processing, con nomi coincidenti con quelli di dipendenti della società.

Infrastruttura e malware

Oltre a TencShell, Hunt.io valuta con confidenza moderata la presenza di un secondo framework C2, finora non documentato, che si autodefinisce Gshell C2
e che opererebbe in parallelo dai medesimi cluster. Il malware recuperato dalle porte di delivery è un binario Linux/ARM a 32 bit, mai osservato prima, denominato HSEWH-Ur
: compilato in Go, comunica via WebSocket verso la porta 4081
dello stesso hub e si autentica con header HTTP X-NITRO-USER
e X-NITRO-PASS
, normalmente usati da API legittime di gestione infrastrutturale.

È in grado di sottrarre credenziali di messaggistica Tencent QQ (inclusi identificativi SDK e chiavi crittografiche), token di piattaforme di enterprise messaging e chiavi di accesso a servizi cloud. Una variante Linux/x86, recuperata da un diverso indirizzo (
38.55.105[.]143:8088
), impiega il tool di offuscamento Go garble
per rimuovere i nomi di funzione; entrambe condividono una chiave di cifratura identica da 80 byte, segno di una codebase comune fra architetture.

Hunt.io si ferma prima di qualificare questi binari come build Linux di TencShell, non avendo confermato una corrispondenza a livello di codice con il campione Windows documentato da Cato. Il filo che lega i due report resta il progetto Reacon: Cato ne aveva trovato la struttura nei path Go di TencShell, e la variante x86 analizzata da Hunt.io impiega garble
proprio per cancellarne i riferimenti.

Perché conta per chi difende

L’attribuzione resta prudente: Hunt.io non nomina un gruppo e si ferma a una valutazione di attività riconducibile alla Cina, sostenuta dalla presenza costante di cinese semplificato nel codice e nelle note, dal clustering a Hong Kong e dal profilo dei bersagli, orientato a procurement, relazioni con i fornitori e visibilità sulle politiche pubbliche.

Per un SOC, il dettaglio più istruttivo è che l’intera catena d’attacco poggiava su strumenti pubblici e leciti assemblati su un’unica macchina: ARL
sulla porta 5003
per la ricognizione, DeepAudit
sulla 3000
per l’audit del codice, Vshell
sulla 8084
per il command-and-control, tutti disponibili apertamente e con usi di testing legittimi. È la loro combinazione, accanto alla directory aperta di dati delle vittime, a distinguere un’intrusione attiva da un normale red team.

Sul piano dei modelli, va evitata un’inferenza affrettata: il report non documenta alcun bypass dei guardrail; gli agenti commerciali, del resto, applicano controlli propri sull’esecuzione, indipendenti da dove nasce il ragionamento.

Lo schema osservato pone piuttosto la questione di come presidiare un uso in cui la componente decisionale viene delegata a un modello terzo, fuori dal perimetro di monitoraggio del vendor che fornisce l’esecuzione. Resta anche una domanda che il report non affronta e che nessuna delle riprese chiarisce: come operatori attivi da Hong Kong, con note in cinese semplificato, abbiano ottenuto accesso a Claude Code
.

Anthropic, nel proprio rapporto di febbraio 2026 sulle distillation attack, dichiarava di non offrire accesso commerciale a Claude in Cina, e descriveva il ricorso di laboratori cinesi a servizi proxy commerciali che rivendono l’accesso ai modelli di frontiera tramite reti di account fraudolenti; il report Hunt.io non collega la campagna a questo canale, e va detto che non lo fa.

A oggi, inoltre, non risultano dichiarate azioni di Anthropic o di DeepSeek sugli account impiegati. I vettori sfruttati, del resto, restano ordinari e prevenibili (SQL injection, segreti hardcoded in JavaScript pubblico, deserializzazione insicura, token cloud non ruotati), e su questi l’igiene applicativa di base continua a fare la differenza.

Il set completo di indicatori, con hash dei file e infrastruttura di rete, è pubblicato nel report originale.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/notizie/cina-claude-code-deepseek-spionaggio-ai/




Two Scattered Spider Hackers Sentenced to Jail in UK

Two members of the Scattered Spider cybercrime group have been sentenced to jail in the United Kingdom, the country’s National Crime Agency (NCA) announced on Thursday.

Thalha Jubair, 20, and Owen Flowers, 18, were charged over their role in a 2024 cyberattack targeting Transport for London (TfL), which caused significant disruptions and generated costs of £29 million ($39 million).

Jubair and Flowers were arrested in September 2025. They initially pleaded not guilty but changed their pleas to guilty when their trial started in June.

On Thursday, they were each sentenced to five years and six months in prison following what officials described as “the largest cybercrime prosecution ever brought before the UK courts”. 

Despite several arrests last year, hackers operating under the Scattered Spider name continued to take credit for cyberattacks through the first months of 2026, although no new attacks have been announced in recent months.

Following the sentencing of Jubair and Flowers, the NCA noted, “Although other cybercriminals may continue to use the damaged Scattered Spider brand, the NCA’s action against Jubair and Flowers effectively halted the group’s criminal activity. Independent assessment supports this, with Microsoft confirming that the arrests materially degraded the group’s ability to continue conducting cybercriminal operations.”

Advertisement. Scroll to continue reading.

In the meantime, authorities continue prosecuting other suspected members of the group. An alleged member, 19-year-old Peter Stokes, a dual US-Estonian national, was recently extradited to the US to face charges. 

Tyler Buchanan, a British national believed to be part of the cybercrime gang, pleaded guilty in a US court in April. 

Related: Third US Security Expert Sentenced to Prison for Helping Ransomware Gang

Related: Romanian Hacker Sentenced to Prison in US for Selling Access to State Network

Related: Third DraftKings Hacker Sentenced to 18 Months in Prison

https://www.securityweek.com/two-scattered-spider-hackers-sentenced-to-jail-in-uk/




AI Data Centers Are Being Built Faster Than They Can Be Secured

The use and reliance on AI is the biggest single growth area in technology. But AI is enormously energy-intensive and requires a new quality of data center. 

The demand is fueling rapid growth in AI data center builds. The danger is that those building this new type of data center, at speed, do not readily understand the difference between traditional data centers and AI data centers – and the result is leaving the new AI data centers open to a new scale of risk. 

Traditional data centers are primarily data processing warehouses serving a known clientele. AI data centers are more akin to high power data compute factories serving a larger and unknown clientele. Traditional data centers can comprise a series of independent servers, an AI data center must function as a single engine capable of massive parallel processing to handle a much greater computational demand. AI data centers simply cannot be built in the same way as traditional data centers.

Lava Labs has examined and now reports (PDF) on the security needs of AI data centers (The Top 10 Data Center and AI Infrastructure Security Risks) and concludes they are being built faster than they are being secured. Both traditional data centers and new AI data centers carry largely similar risks; but AI changes their exploitability and blast radius: “Systems originally designed for trusted operators are now supporting high-value, multi-tenant workloads from unrelated customers,” it notes.

The Lava Labs report lists the top ten AI data center and infrastructure security risks, naming them ‘Forge’ (because the purpose is to ‘harden the metal beneath the model’).

  • Forge 01: firmware and hardware integrity compromise
  • Forge 02: network and interconnect vulnerabilities
  • Forge 03: unsafe multi‑tenant isolation and resource reuse
  • Forge 04: insecure out‑of‑band management plane
  • Forge 05: AI infrastructure supply chain compromise
  • Forge 06: insecure facility and data center management systems
  • Forge 07: insecure data and artifact handling
  • Forge 08: certification gaps and provider transparency failures
  • Forge 09: insecure operational infrastructure services
  • Forge 10: vendor embargo gaps and patch velocity failures

The sequencing of these risks is primarily based on severity. Risks 01 to 05 operate below the operating system, are difficult to detect, and have a cluster-wide blast radius. Risks 06 to 09 are generally easier to detect and recover from. Risk 10 is the easiest to detect and remediate; and is the least likely to cause catastrophic tenant compromise.

FORGE IDs are ordered by severity, from highest to lowest. The matrix groups each risk by domain and shows its likelihood, impact, and detection difficulty.

The risks arise because the nature of AI breaks the basic trust model of traditional data centers. For 03, 07, and 08. AI introduces unrelated commercial tenants, high‑value workloads, and GPU nodes that are reassigned between customers. 

For 01, 06 and 10, new hardware realities from the dense GPU clusters require complex firmware stacks, have extreme thermal sensitivity, and a larger blast radius for facility failures. 

Advertisement. Scroll to continue reading.

For 02, the required high performance fabrics such as InfiniBand, RoCE, RDMA, and NVLink are often unencrypted, poorly monitored, and highly privileged. Weak fabric isolation can expose paths to discovery, abuse, or lateral movement. 

In 04 and 09, an operational concentration of privilege can result from a heavy reliance on BMC automation, Redfish/IPMI, firmware pipelines, and orchestration systems.

For 05 and 10, a scarcity of GPU processors often means that new AI data centers opt for processors that are less suitable, with weaker isolation that can lead to more likely supply chain compromise.

The functional purpose of Lava Labs analysis and report is threefold: to expose the unique risks of AI data centers; to prioritize the most severe risks, thus effectively providing a triage sequence; and to provide example attack scenarios and practical mitigations for those risks.

The moral from the Lava Labs analysis is, yes, you will need a new data center to feed your AI; but, no, you cannot use your existing data center model as a design blueprint.

Learn More at the AI Risk Summit | Ritz-Carlton, Half Moon Bay

Related: Trump’s New AI Plan Leans Heavily on Silicon Valley Industry Ideas

Related: Pentagon Paid Out $290,000 for Vulnerabilities in Air Force Data Center

Related: Intel TDX Connect Bridges the CPU-GPU Security Gap

https://www.securityweek.com/ai-data-centers-are-being-built-faster-than-they-can-be-secured/




‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

A new macOS malware named ClickLock Stealer leverages social engineering and process killing to bypass the operating system’s protections and obtain valuable information from victims. 

Cybersecurity firm Group-IB came across ClickLock Stealer in early June, and the malware appears to have been around since at least late May. Researchers say it has targeted at least 100 users across 33 countries, more than half in Europe.

The stealer is designed to collect various types of data from compromised systems, including web browsers, cryptocurrency wallets and wallet extensions, and password manager extensions. It can also harvest blockchain addresses from six chains and target the macOS Keychain, FTP credentials, and shell history. The stolen data is added to an archive file and exfiltrated to a Telegram bot.

While Group-IB researchers could not definitively determine how ClickLock Stealer is distributed, they believe threat actors may have used SEO poisoning, social media posts, or compromised websites to lure victims to a ClickFix attack page disguised as a Cloudflare verification. 

Users who land on this page are instructed to copy a bash command, paste it into macOS’s Terminal, and execute it. Once the command is run, an orchestrator script file is downloaded and executed, which in turn fetches four other scripts representing a credential stealer, a cryptocurrency stealer, a Keychain stealer, and a backdoor installer. 

The backdoor remains on the compromised machine, but the other scripts are removed once they have harvested the targeted data and sent it back to the attacker.

Advertisement. Scroll to continue reading.

macOS’s design and built-in protections make it harder to deploy malware. However, ClickLock Stealer succeeds primarily through social engineering because the malware is downloaded and executed directly by the victim with their own privileges. Unlike other malware, it does not need exploits or privilege escalation. 

To access the targeted data, the malware employs aggressive process-killing loops. The orchestrator component displays a fake macOS dialog to capture the user’s password, killing every visible process so that only the password window is shown on the screen until the victim complies.

“A background loop also starts killing macOS NotificationCenter continuously for approximately ~6 hours, suppressing any Gatekeeper or security warnings that might alert the victim,” Group-IB explained in a blog post describing ClickLock Stealer. 

Other components also aggressively terminate applications that the victim may use to analyze or disrupt the attack. The credential stealer component also displays a fake macOS password dialog and keeps it open in a long loop while other applications are terminated, forcing the victim to enter the password. 

When the malware queries the macOS Keychain for the Chrome Safe Storage encryption key, which protects passwords and other browser data, the user is prompted to authorize the action. Again, all processes are killed until the user complies and Keychain access is granted.

Related: macOS Weaknesses Chained to Silently Disable Endpoint Security Agents

Related: MacSync macOS Malware Distributed via Signed Swift Application

Related: Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari

https://www.securityweek.com/clicklock-stealer-bypasses-macos-security-with-social-engineering-process-killing/




Oak Emerges From Stealth Mode With $60 Million in Funding

Israeli cybersecurity startup Oak has emerged from stealth mode with $60 million in seed funding to build an AI-powered Identity Operating System.

The investment round was co-led by Accel, Greylock Partners, and CRV, with additional support from Hetz Ventures, AlphaDrive Ventures, and angel investors.

Founded in late 2025, Tel Aviv- and San Francisco-based Oak has built a platform that unifies identity governance within a single, continuously updated control plane.

Already generally available, Oak’s Identity Operating System aims to replace legacy identity governance and security tools with a single solution covering all human, AI, and machine identities across an organization’s environment.

The platform connects to an organization’s applications across cloud, on-premises, SaaS, and homegrown systems to build connectors within hours, understanding each identity based on raw evidence instead of static records.

By creating a map of each identity’s access against what it uses, Oak’s platform provides identity governance throughout the entire lifecycle, complemented by AI-driven real-time risk decisions and remediation.

Advertisement. Scroll to continue reading.

Oak was co-founded by Shai Morag (Chief Executive Officer), who previously founded Integrity-Project (acquired by NVIDIA’s Mellanox), Secdo (acquired by Palo Alto Networks), and Ermetic (acquired by Tenable); and Tal Marom (Chief Product Officer), who previously led product teams at Tenable and Salesforce.

“We spent months speaking with more than 100 CISOs and IAM leaders, and they all share the same problems of running too many disconnected tools, being unable to see how access is used, and having no way to govern AI agents,” Marom said.

“Just as CNAPP consolidated the fragmented cloud security stack, identity is now at that same inflection point, and Oak is designed to be the platform that brings it all together and turbocharges the security teams defending the enterprise,” Marom added.

Related: Valarian Raises $50 Million for Sovereign Infrastructure Control Layer

Related: QIZ Security Raises $17 Million for Cryptographic Governance Platform

Related: 8Layers Raises $2.9 Million for Identity Security Platform

Related: Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security

https://www.securityweek.com/oak-emerges-from-stealth-mode-with-60-million-in-funding/




Splunk, Zoom Patch Critical Vulnerabilities

Splunk and Zoom this week announced patches for multiple vulnerabilities across their products, including several critical and high-severity security defects.

Only three of the five advisories that Splunk published address flaws that are specific to its products, while the other two resolve dozens of bugs in third-party components.

The Splunk-specific issues include CVE-2026-20296 (a high-severity command safeguards bypass), CVE-2026-20297 (a high-severity path traversal), and CVE-2026-20298 (a medium-severity information disclosure).

Successful exploitation of these weaknesses could allow attackers to access credentials and data, write files outside the intended application directory, and view stored credential hashes.

Patches for all three were included in Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, and 9.4.13, which also address critical- and high-severity vulnerabilities in Golang, Go compiler, OpenSSL, and other third-party libraries.

Zoom published four advisories that resolve as many vulnerabilities across its clients and tools for Windows.

Advertisement. Scroll to continue reading.

The most severe is CVE-2026-53412 (CVSS score of 9.8), a critical bug in Zoom’s Workplace and Workplace VDI Client for Windows that could allow remote, unauthenticated attackers to mount account takeover attacks.

The company’s updates also resolve three high-severity flaws: a time-of-check-to-time-of-use (TOCTOU) race condition and two privilege elevation issues.  

Neither Splunk nor Zoom makes any mention of these vulnerabilities being exploited in the wild.

Related: F5 Patches Multiple NGINX, BIG-IP Vulnerabilities

Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

Related: Old UEFI Shims Expose Systems to Secure Boot Bypass

Related: CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

https://www.securityweek.com/splunk-zoom-patch-critical-vulnerabilities/




F5 Patches Multiple NGINX, BIG-IP Vulnerabilities

F5 on Wednesday announced an out-of-band security rollout that patches eight vulnerabilities in NGINX and BIG-IP.

The most severe flaw is CVE-2026-42533 (CVSS score of 9.2), a critical issue in NGINX Plus and NGINX Open Source that could be exploited via crafted HTTP requests to cause a heap buffer overflow and restart the NGINX worker process.

“A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map’s regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions,” F5 explains.

An attacker can exploit the security defect without authentication, but only under conditions they cannot control. On systems with Address Space Layout Randomization (ASLR) disabled, the attacker can achieve code execution.

F5’s patches also resolve several high-severity NGINX bugs, including weaknesses in the ngx_http_slice_module module and the ngx_http_ssi_module module that can be exploited without authentication.

Successful exploitation of the flaws allows attackers to leak memory contents, restart the NGINX worker process, or cause a use-after-free in the NGINX worker process to modify memory or restart the process.

Advertisement. Scroll to continue reading.

Two high-severity vulnerabilities addressed in NGINX Ingress Controller could allow authenticated attackers to inject arbitrary NGINX configuration directives to delete files and disable services, or create or modify Ingress or TransportServer resources to cause a denial-of-service (DoS) condition.

F5 also resolved a high-severity security defect in BIG-IP that could be exploited by remote, unauthenticated attackers to increase memory resource utilization when an HTTP/2 profile is configured on a virtual server, causing a DoS condition.

F5 makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found in the company’s out-of-band security notification.

Related: Trend Micro, Tanium, ESET, and Tenable Patch Severe Product Vulnerabilities

Related: Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell

Related: Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates

https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities/




Hazel Cerra — Women in Security 2026

During her time with the U.S. Secret Service, Hazel Cerra found herself at the precipice of the rise of cybercrime. Cerra noticed how digital evidence was becoming increasingly prevalent with each investigation. “I volunteered for technical assignments and pursued opportunities to build expertise in cyber investigations and critical systems protection,” Cerra says.

Taking initiative paid off quickly, as Cerra found herself with the perfect skillset for oncoming challenges.

“Looking back, one of the most important lessons I learned was that growth often comes from stepping into gaps rather than following the crowd. Choosing that path early in my career shaped the opportunities that followed and ultimately influenced the direction of my professional life,” Cerra says.

Cerra served with the U.S. Secret Service for more than 20 years, leading investigations, conducting protective operations and advancing security initiatives.

In the early years of Cerra’s career, she investigated multimillion-dollar financial fraud cases before she was selected for a full-time protective assignment for President Bill Clinton. Here, Cerra protected the President for four years during engagements related to the Clinton Global Initiative.

Cerra was also the Resident Agent in Charge of the Atlantic City Resident Office. In this role she strengthened partnerships with local chiefs of police and federal partners. One of Cerra’s accomplishments includes the National Computer Forensics Institute network, which helps local law enforcement community access cyber investigative training and resources.

Currently, Cerra serves as the Director of Digital Security Convergence at BlackCloak.

“What I find most rewarding is helping others see risks from a different perspective and providing practical solutions that improve security outcomes. Every day, I have the opportunity to draw upon decades of investigative, cyber, and protective experience to support a mission I deeply believe in, helping organizations better protect the people who matter most,” Cerra says.

Cerra carries this same sentiment into her mentorship opportunities. During her time in the U.S. Secret Service, Cerra worked alongside “exceptional leaders” who “set the standard” for understanding and executing a security objective. Cerra’s mentors advocated for her to pursue specialized training in network intrusion investigations and critical systems protection, providing countless opportunities for her throughout her career.

“As my career progressed, I made a conscious commitment to pay that mentorship forward. Whether mentoring Special Agents, supporting law enforcement partners, or developing future security professionals, I have always believed that investing in people is one of the most important responsibilities of leadership,” Cerra says.

Cerra’s mentorship spans beyond the workplace, including her role as an adjunct professor at New Jersey City University. Cerra teaches Leadership for Women in Security, helping students build skills, confidence, and demonstrating how to create an inclusive environment.

“Growth often comes from stepping into gaps rather than following the crowd.”

“Over the years, I have learned that success is rarely achieved alone. Some of my most important lessons came not from assignments or promotions, but from navigating challenges and discovering who was willing to stand beside me when circumstances were difficult,” Cerra says.

Additionally, Cerra serves as a CyberPatriot coach with the Civil Air Patrol. This role includes mentoring students participating in national cybersecurity competition and encouraging young individuals to pursue cybersecurity career pathways.

“The greatest lesson mentorship taught me is that leadership is not measured by individual achievement, but by the success of those you help develop. The investment others made in me shaped my career, and I am committed to ensuring that same opportunity exists for those who follow,” Cerra says. “More than any professional achievement, I am proud of the relationships I have built and the trust I have earned throughout my career.”

Cerra leaves this advice to rising security leaders: “Do not let others define your limits. Be willing to pursue opportunities that interest you, even if others question your path or tell you something cannot be done. Some of the most rewarding opportunities in my career came from stepping into unfamiliar territory and taking calculated risks.”

https://www.securitymagazine.com/articles/102430-hazel-cerra-women-in-security-2026




China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans

China’s military procurement system has suspended or permanently barred more than a dozen of the country’s leading cybersecurity vendors since 2024, according to new research from threat intelligence group Natto Thoughts. 

The findings, based on public notices from the military procurement network cross-referenced with corporate disclosures and Chinese media reports, identify at least 21 enforcement actions between 2021 and 2026 tied to contract bidding misconduct rather than product or technical failures.

The penalties fall under a three-tier system used by the People’s Liberation Army (PLA): a private warning list for early-stage concerns, a suspension list for confirmed but limited violations, and a public blacklist reserved for serious offenses that can carry lifetime bans extending to affiliated companies and executives.

[ Read: China, India-Linked Hackers Both Targeted Same Pakistani Police Force ]

One example is Beijing TopSec Network Security, an indirect subsidiary of TopSec Technologies Group. In 2024, the company was suspended from specific services for three years after it was accused of collusive bidding on an Army contract, but investigators later expanded the suspension to cover all military branches. In January 2026, following a two-year probe, authorities imposed a lifetime ban on all military procurement, the maximum penalty available.

Venustech Group followed a similar trajectory, but the impact on the company was less severe. Its subsidiary, Beijing Venustech Information Security Technology, was suspended from a regional military command in August 2024 and from all military bidding in February 2025. In April 2026, the sanctions escalated to include the parent company itself. However, the action remains a suspension rather than a permanent ban.

Advertisement. Scroll to continue reading.

Other firms named in the research include Qi An Xin’s Legendsec subsidiary, digital certificate provider BJCA, Kylinsec, Westone (CETC Cyber Security), and Huaru Technologies. Several of these companies are publicly traded or holders of classified systems and defense-related qualifications.

These firms occupy a dual role in China’s security ecosystem, according to Eugenio Benincasa, a China-focused cybersecurity researcher at ETH Zurich, who co-authored the report [subscription required] with Natto Thoughts co-founder Mei Danowski.

On the defensive side, Benincasa told SecurityWeek, companies like TopSec and Venustech pioneered China’s firewall market, while Qi An Xin has built a strong position in threat intelligence. 

None of the firms have been publicly linked to directly operating offensive hacking groups, Benincasa said, but they have long-standing ties to the PLA and China’s security services, supporting military cyber operations through training and service provision, and, in Qi An Xin’s case, through investments in companies tied to known Chinese APT activity.

The Natto team ties the increase in enforcement to a broader shift in PLA procurement oversight, including 2024 regulations on competitive bidding for military equipment and the growing enforcement role of China’s newly formed Cyberspace Force, which the report credits with six of the reviewed violation cases.

The researchers also point to commercial pressure as a contributing factor. For instance, Venustech’s early-2025 outlook cited softening security budgets and a market pivot toward AI- and data-driven demand, a shift that TopSec appears to be navigating as well.

Despite the penalties, the report concludes that the Chinese military still depends heavily on these firms for modernization, framing the crackdown as an effort to professionalize defense acquisition rather than evidence that China’s cybersecurity capabilities are weakening.

Related: Chinese Cybersecurity Firm’s AI Hacking Claims Draw Comparisons to Claude Mythos

Related: China Revives Tianfu Cup Hacking Contest Under Increased Secrecy

Related: Cybersecurity Firms React to China’s Reported Software Ban

https://www.securityweek.com/chinas-top-cybersecurity-firms-hit-by-mounting-military-procurement-bans/